Please do not open a public issue for security vulnerabilities.
Preferred: use this repository's Security tab → Report a vulnerability to file a private advisory, if enabled.
Alternative: email david@writerslogic.com with details and steps to reproduce.
You should expect an initial response within a few days. If the issue is confirmed, a fix will be prioritized and a coordinated disclosure timeline agreed on before any public advisory.
Unless a repository states otherwise, only the latest released version receives security fixes.